Contact | Site en Français               

 


 

VUPEN VNS v4.0

 
  Features and Options
  Free 14-Day Trial

  Partner Program

  Receive More Information
 
   
 

Latest Intelligence

 
  VUPEN Security Advisories

  Virus and Malware Alerts

  VUPEN Security Research
  Threat Watch Blog
  Zero-Day Monitor
  Search Engine
  Mailing List & RSS
 
   

>> Microsoft Windows Secure Channel Spoofing Vulnerability (MS09-007)

Title : Microsoft Windows Secure Channel Spoofing Vulnerability (MS09-007)
VUPEN ID : VUPEN/ADV-2009-0660
CVE ID : CVE-2009-0085
CWE ID : VUPEN VNS Only
CVSS V2 : VUPEN VNS Only
Rated as : Moderate Risk 
Remotely Exploitable : Yes
Locally Exploitable : Yes
Release Date : 2009-03-10


Technical Description    Receive VUPEN Security alerts in a Text format  Receive VUPEN Security alerts in a PDF format  Receive VUPEN Security alerts in an XML format 

A vulnerability has been identified in Microsoft Windows, which could be exploited by attackers to bypass security restrictions. This issue is caused by an error in the Secure Channel (SChannel) authentication component that does not apply sufficient validation of certain Transport Layer Security (TLS) handshake messages to ensure that the client does in fact have access to the private key linked to the certificate used for authentication, which could allow attackers to authenticate to a server using only an authorized user's digital certificate and without the associated private key.

Affected Products

Microsoft Windows 2000 Service Pack 4
Microsoft Windows XP Service Pack 2
Microsoft Windows XP Service Pack 3
Microsoft Windows XP Professional x64 Edition
Microsoft Windows XP Professional x64 Edition Service Pack 2
Microsoft Windows Server 2003 Service Pack 1
Microsoft Windows Server 2003 Service Pack 2
Microsoft Windows Server 2003 x64 Edition
Microsoft Windows Server 2003 x64 Edition Service Pack 2
Microsoft Windows Server 2003 SP1 (Itanium)
Microsoft Windows Server 2003 SP2 (Itanium)
Microsoft Windows Vista
Microsoft Windows Vista Service Pack 1
Microsoft Windows Vista x64 Edition
Microsoft Windows Vista x64 Edition Service Pack 1
Microsoft Windows Server 2008 (32-bit)
Microsoft Windows Server 2008 (x64)
Microsoft Windows Server 2008 (Itanium)

Solution

Apply patch for Microsoft Windows 2000 Service Pack 4 :
http://www.microsoft.com/downloads/details.aspx?familyid=bf7065bc-c183-4a78-8d46-72fe7385c07c

Apply patch for Microsoft Windows XP SP2 and SP3 :
http://www.microsoft.com/downloads/details.aspx?familyid=942d87f6-3cb1-4d36-a70a-70d9c34488f3

Apply patch for Microsoft Windows XP Professional x64 Edition and Windows XP Professional x64 Edition Service Pack 2 :
http://www.microsoft.com/downloads/details.aspx?familyid=6d02306e-9e2e-4ae8-bd21-8a2c1a229472

Apply patch for Microsoft Windows Server 2003 Service Pack 1 and Windows Server 2003 Service Pack 2 :
http://www.microsoft.com/downloads/details.aspx?familyid=0b3f6fdd-276e-4267-99d8-8f00d91ad6a2

Apply patch for Microsoft Windows Server 2003 x64 Edition and Windows Server 2003 x64 Edition Service Pack 2 :
http://www.microsoft.com/downloads/details.aspx?familyid=ce98ff55-f565-469d-bbd2-32b681faf908

Apply patch for Microsoft Windows Server 2003 with SP1 for Itanium-based Systems and Windows Server 2003 with SP2 for Itanium-based Systems :
http://www.microsoft.com/downloads/details.aspx?familyid=5ca3c72c-cadb-4b0a-b3a3-fb81d0bfd7b3

Apply patch for Microsoft Windows Vista and Windows Vista Service Pack 1 :
http://www.microsoft.com/downloads/details.aspx?familyid=21086a04-402a-4940-8358-7fa63508102b

Apply patch for Microsoft Windows Vista x64 Edition and Windows Vista x64 Edition Service Pack 1 :
http://www.microsoft.com/downloads/details.aspx?familyid=c75a2ea9-b42f-457b-be09-5c8fa0339388

Apply patch for Microsoft Windows Server 2008 for 32-bit Systems :
http://www.microsoft.com/downloads/details.aspx?familyid=47b361ce-624b-466c-b5c5-8703f6532615

Apply patch for Microsoft Windows Server 2008 for x64-based Systems :
http://www.microsoft.com/downloads/details.aspx?familyid=5c81ac45-60e6-4121-ab6b-d3b3179aacc4

Apply patch for Microsoft Windows Server 2008 for Itanium-based Systems :
http://www.microsoft.com/downloads/details.aspx?familyid=bf8f5a86-1757-4f9b-b632-d4aa7005a9f8

References

http://www.vupen.com/english/advisories/2009/0660
http://www.microsoft.com/technet/security/Bulletin/MS09-007.mspx

Credits

Vulnerabilities reported by Secretaria da Fazenda do Estado do Rio Grande do Sul and Cia de Processamento de Dados do Estado do Rio Grande do Sul.

ChangeLog

2009-03-10 : Initial release

Vulnerability Management

Subscribe to VUPEN VNS and receive real-time alerts with CVE, CWE, and CVSS when new advisories or patches relevant to your systems and network configurations are available.

Feedback

If you have additional information or corrections for this security advisory please submit them via our contact form.

 

VUPEN Vulnerability
Notification Service

 

Latest Advisories

  

   
    





Copyright VUPEN © 2004-2010 - Privacy Policy